<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aadobelightroomclassic/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 23:42:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aadobelightroomclassic/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Adobe Security Updates — August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/</link><pubDate>Mon, 03 Aug 2026 23:42:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/</guid><description>Roundup of Adobe security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 49 Adobe security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Campaign Classic, Adobe Commerce, Adobe Substance 3D Designer, Adobe Substance 3D Painter, Adobe Substance 3D Sampler, ColdFusion, ColdFusion 2025, Content Credentials Rust SDK, Lightroom Classic, Substance 3D Painter, Substance 3D Sampler.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-48362">CVE-2026-48362</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>4.31%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48362">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71384">CVE-2026-71384</a></td>
					<td>n/a</td>
					<td>Critical</td>
					<td>9.6</td>
					<td>0.37%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71384">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-21273">CVE-2026-21273</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21273">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-21279">CVE-2026-21279</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>8.2</td>
					<td>0.47%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21279">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-25652">CVE-2026-25652</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.14%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25652">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-34635">CVE-2026-34635</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>8.4</td>
					<td>0.18%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34635">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48385">CVE-2026-48385</a></td>
					<td>ColdFusion (&lt;= 2025.0.11)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48385">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48386">CVE-2026-48386</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48386">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48439">CVE-2026-48439</a></td>
					<td>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.51%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48439">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48440">CVE-2026-48440</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>8.1</td>
					<td>0.55%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48440">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48442">CVE-2026-48442</a></td>
					<td>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</td>
					<td>High</td>
					<td>7.1</td>
					<td>0.24%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48442">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-27302">CVE-2026-27302</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>0.71%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27302">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71362">CVE-2026-71362</a></td>
					<td>n/a</td>
					<td>Critical</td>
					<td>9.1</td>
					<td>25.14%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71362">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71398">CVE-2026-71398</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td>0.79%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71398">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-47940">CVE-2026-47940</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47940">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48397">CVE-2026-48397</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48397">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48405">CVE-2026-48405</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48405">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48406">CVE-2026-48406</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48406">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48407">CVE-2026-48407</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48407">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48408">CVE-2026-48408</a></td>
					<td>Lightroom Classic (&lt;= 15.4)</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48408">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48410">CVE-2026-48410</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td>0.16%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48410">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48413">CVE-2026-48413</a></td>
					<td>Adobe Commerce (&lt;= 2026-07-31)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48413">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48415">CVE-2026-48415</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.6</td>
					<td>0.35%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48415">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48416">CVE-2026-48416</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.50%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48416">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48447">CVE-2026-48447</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.7</td>
					<td>0.14%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48447">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76193">CVE-2026-76193</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76193">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76195">CVE-2026-76195</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76195">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76197">CVE-2026-76197</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76197">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48417">CVE-2026-48417</a></td>
					<td>Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48417">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48418">CVE-2026-48418</a></td>
					<td>Adobe Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48418">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48419">CVE-2026-48419</a></td>
					<td>Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48419">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48420">CVE-2026-48420</a></td>
					<td>Adobe Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48420">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48421">CVE-2026-48421</a></td>
					<td>Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48421">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48424">CVE-2026-48424</a></td>
					<td>Adobe Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48424">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48426">CVE-2026-48426</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48426">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48427">CVE-2026-48427</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48427">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48428">CVE-2026-48428</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48428">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48430">CVE-2026-48430</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48430">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48432">CVE-2026-48432</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48432">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48433">CVE-2026-48433</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48433">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71360">CVE-2026-71360</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71360">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71382">CVE-2026-71382</a></td>
					<td>Substance 3D Sampler (&lt;= 6.0.1)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71382">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71443">CVE-2026-71443</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71443">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71564">CVE-2026-71564</a></td>
					<td>Adobe Substance 3D Designer (&lt;= 16.0.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71564">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75749">CVE-2026-75749</a></td>
					<td>Adobe Substance 3D Painter (&lt;= 12.1.2)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75749">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75750">CVE-2026-75750</a></td>
					<td>Adobe Substance 3D Painter (&lt;= 12.1.2)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75750">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75766">CVE-2026-75766</a></td>
					<td>Substance 3D Painter (&lt;= 12.1.2)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75766">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75768">CVE-2026-75768</a></td>
					<td>Substance 3D Painter (&lt;= 12.1.2)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75768">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-75769">CVE-2026-75769</a></td>
					<td>Substance 3D Painter (&lt;= 12.1.2)</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75769">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-48362">CVE-2026-48362</h2>
<p>CVE-2026-48362 is a critical OS command injection vulnerability in Adobe ColdFusion 2023 and 2025 that allows unauthenticated, remote attackers to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the scope of the application, posing a significant risk to affected environments.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48362">https://nvd.nist.gov/vuln/detail/CVE-2026-48362</a></p>
<p>Related in this roundup: <a href="#cve-2026-21273">CVE-2026-21273</a>, <a href="#cve-2026-48386">CVE-2026-48386</a>.</p>
<h2 id="cve-2026-71384">CVE-2026-71384</h2>
<p>CVE-2026-71384 is an incorrect authorization vulnerability in Adobe ColdFusion 2023 and 2025. The flaw allows an unauthenticated, adjacent attacker to bypass security features, resulting in unauthorized read and write access, and potentially a denial-of-service condition. Although the vulnerable component is restricted to an administrative network zone by default, successful exploitation does not require user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71384">https://nvd.nist.gov/vuln/detail/CVE-2026-71384</a></p>
<h2 id="cve-2026-21273">CVE-2026-21273</h2>
<p>CVE-2026-21273 describes an improper input validation vulnerability in Adobe ColdFusion 2025 and 2023. A low-privileged attacker can exploit this flaw by enticing a user to open a malicious file, leading to unauthorized read and write access and privilege escalation on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21273">https://nvd.nist.gov/vuln/detail/CVE-2026-21273</a></p>
<p>Related in this roundup: <a href="#cve-2026-48362">CVE-2026-48362</a>, <a href="#cve-2026-48386">CVE-2026-48386</a>.</p>
<h2 id="cve-2026-21279">CVE-2026-21279</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) are vulnerable to an improper input validation flaw that allows for a security feature bypass. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized read and limited write access to the affected system without requiring user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21279">https://nvd.nist.gov/vuln/detail/CVE-2026-21279</a></p>
<h2 id="cve-2026-25652">CVE-2026-25652</h2>
<p>CVE-2026-25652 is an Incorrect Authorization vulnerability in Adobe ColdFusion 2025 and 2023 versions. A low-privileged attacker can exploit this flaw to escalate privileges and gain unauthorized read and write access to the system. Exploitation is local and does not require user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25652">https://nvd.nist.gov/vuln/detail/CVE-2026-25652</a></p>
<h2 id="cve-2026-34635">CVE-2026-34635</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker can exploit this issue to bypass security features and obtain unauthorized read and write access without user interaction. The vulnerability results in a scope change, potentially allowing for cross-security-domain impact.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34635">https://nvd.nist.gov/vuln/detail/CVE-2026-34635</a></p>
<h2 id="cve-2026-48385">CVE-2026-48385</h2>
<p>Adobe ColdFusion is vulnerable to an OS command injection flaw (CVE-2026-48385) that allows low-privileged, remote attackers to bypass security features and gain unauthorized write access to the system. The vulnerability does not require user interaction and impacts the system scope.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion (&lt;= 2025.0.11)</li>
<li>ColdFusion (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48385">https://nvd.nist.gov/vuln/detail/CVE-2026-48385</a></p>
<h2 id="cve-2026-48386">CVE-2026-48386</h2>
<p>Adobe ColdFusion is vulnerable to a broken or risky cryptographic algorithm (CWE-327), which can be exploited by a remote, unauthenticated attacker to disclose sensitive memory contents. Successful exploitation allows for the unauthorized access to sensitive information without requiring user interaction.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48386">https://nvd.nist.gov/vuln/detail/CVE-2026-48386</a></p>
<p>Related in this roundup: <a href="#cve-2026-48362">CVE-2026-48362</a>, <a href="#cve-2026-21273">CVE-2026-21273</a>.</p>
<h2 id="cve-2026-48439">CVE-2026-48439</h2>
<p>The CAI Content Credentials SDKs and command-line tool are vulnerable to an uncontrolled resource consumption issue (CWE-400). A remote, unauthenticated attacker can exploit this vulnerability to exhaust system resources, leading to a denial-of-service (DoS) condition. No user interaction is required for successful exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</li>
<li>Content Credentials Command-Line Tool (&lt;= c2patool-v0.27.5)</li>
<li>Content Credentials JS SDK (&lt;= @contentauth/c2pa@0.14.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48439">https://nvd.nist.gov/vuln/detail/CVE-2026-48439</a></p>
<p>Related in this roundup: <a href="#cve-2026-48442">CVE-2026-48442</a>.</p>
<h2 id="cve-2026-48440">CVE-2026-48440</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) are vulnerable to a heap-based buffer overflow. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code in the context of the current user without requiring user interaction. The exploitation process is non-deterministic, relying on specific environmental conditions.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48440">https://nvd.nist.gov/vuln/detail/CVE-2026-48440</a></p>
<h2 id="cve-2026-48442">CVE-2026-48442</h2>
<p>The Adobe Content Credentials SDK and associated tooling are vulnerable to a path traversal vulnerability (CWE-22) which allows an attacker to perform arbitrary file system reads. The vulnerability does not require user interaction and impacts multiple language-specific SDKs and the CLI tool.</p>
<p>Affected products:</p>
<ul>
<li>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</li>
<li>Content Credentials Command-Line Tool (&lt;= c2patool-v0.27.5)</li>
<li>Content Credentials JS SDK (&lt;= @contentauth/c2pa-v0.27.5)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48442">https://nvd.nist.gov/vuln/detail/CVE-2026-48442</a></p>
<p>Related in this roundup: <a href="#cve-2026-48439">CVE-2026-48439</a>.</p>
<h2 id="cve-2026-27302">CVE-2026-27302</h2>
<p>Adobe Campaign Classic is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS v3.1 base score of 10.0 and does not require user interaction to exploit.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27302">https://nvd.nist.gov/vuln/detail/CVE-2026-27302</a></p>
<p>Related in this roundup: <a href="#cve-2026-71398">CVE-2026-71398</a>, <a href="#cve-2026-76193">CVE-2026-76193</a>, <a href="#cve-2026-76195">CVE-2026-76195</a>, <a href="#cve-2026-76197">CVE-2026-76197</a>.</p>
<h2 id="cve-2026-71362">CVE-2026-71362</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to perform privilege escalation. The vulnerability does not require user interaction and can be exploited to gain unauthorized access to sensitive resources.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71362">https://nvd.nist.gov/vuln/detail/CVE-2026-71362</a></p>
<h2 id="cve-2026-71398">CVE-2026-71398</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS base score of 10.0 and does not require user interaction for exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71398">https://nvd.nist.gov/vuln/detail/CVE-2026-71398</a></p>
<p>Related in this roundup: <a href="#cve-2026-27302">CVE-2026-27302</a>, <a href="#cve-2026-76193">CVE-2026-76193</a>, <a href="#cve-2026-76195">CVE-2026-76195</a>, <a href="#cve-2026-76197">CVE-2026-76197</a>.</p>
<h2 id="cve-2026-47940">CVE-2026-47940</h2>
<p>Adobe Lightroom Classic is vulnerable to an integer overflow or wraparound condition that can lead to arbitrary code execution. The vulnerability is triggered when a user is enticed to open a maliciously crafted file, allowing an attacker to execute code within the context of the current user session.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47940">https://nvd.nist.gov/vuln/detail/CVE-2026-47940</a></p>
<h2 id="cve-2026-48397">CVE-2026-48397</h2>
<p>Adobe Lightroom Classic is vulnerable to a deserialization of untrusted data issue that allows an attacker to achieve arbitrary code execution. The vulnerability requires user interaction, specifically the opening of a malicious file by the victim, which triggers the flaw within the application context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48397">https://nvd.nist.gov/vuln/detail/CVE-2026-48397</a></p>
<h2 id="cve-2026-48405">CVE-2026-48405</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) flaw that allows an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption within the application context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48405">https://nvd.nist.gov/vuln/detail/CVE-2026-48405</a></p>
<h2 id="cve-2026-48406">CVE-2026-48406</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. A local attacker can exploit this by convincing a user to open a specially crafted malicious file within the application.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48406">https://nvd.nist.gov/vuln/detail/CVE-2026-48406</a></p>
<h2 id="cve-2026-48407">CVE-2026-48407</h2>
<p>Adobe Lightroom Classic is susceptible to an out-of-bounds write vulnerability that can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption issue within the application's process context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48407">https://nvd.nist.gov/vuln/detail/CVE-2026-48407</a></p>
<h2 id="cve-2026-48408">CVE-2026-48408</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the vulnerability in the context of the logged-in user.</p>
<p>Affected products:</p>
<ul>
<li>Lightroom Classic (&lt;= 15.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48408">https://nvd.nist.gov/vuln/detail/CVE-2026-48408</a></p>
<h2 id="cve-2026-48410">CVE-2026-48410</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write, which can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires the user to open a malicious file, making it a client-side execution risk.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48410">https://nvd.nist.gov/vuln/detail/CVE-2026-48410</a></p>
<h2 id="cve-2026-48413">CVE-2026-48413</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to a stored Cross-Site Scripting (XSS) attack via malicious input in form fields. A low-privileged attacker can inject scripts that execute in a victim's browser, potentially leading to unauthorized account or session control. This vulnerability involves a change in security scope.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Commerce (&lt;= 2026-07-31)</li>
<li>Adobe Commerce B2B (&lt;= 2026-07-31)</li>
<li>Magento Open Source (&lt;= 2026-07-31)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48413">https://nvd.nist.gov/vuln/detail/CVE-2026-48413</a></p>
<h2 id="cve-2026-48415">CVE-2026-48415</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows a low-privileged, remote attacker to bypass security controls. Successful exploitation grants unauthorized read and write access without requiring user interaction, potentially impacting data integrity and availability.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48415">https://nvd.nist.gov/vuln/detail/CVE-2026-48415</a></p>
<h2 id="cve-2026-48416">CVE-2026-48416</h2>
<p>CVE-2026-48416 is an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows remote, unauthenticated attackers to bypass security measures and gain unauthorized read access to sensitive data. The vulnerability does not require user interaction and is exploitable over the network.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48416">https://nvd.nist.gov/vuln/detail/CVE-2026-48416</a></p>
<h2 id="cve-2026-48447">CVE-2026-48447</h2>
<p>Adobe Lightroom Classic is vulnerable to an incorrect authorization flaw (CWE-863) that can be exploited to achieve arbitrary code execution. The vulnerability is triggered when a user opens a maliciously crafted file. Successful exploitation requires user interaction and specific conditions beyond the attacker's control.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48447">https://nvd.nist.gov/vuln/detail/CVE-2026-48447</a></p>
<h2 id="cve-2026-76193">CVE-2026-76193</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to a Server-Side Request Forgery (SSRF) flaw, identified as CVE-2026-76193. An unauthenticated, remote attacker can leverage this vulnerability to execute arbitrary code within the context of the service user without any interaction required. The vulnerability carries a critical CVSS v3.1 score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76193">https://nvd.nist.gov/vuln/detail/CVE-2026-76193</a></p>
<p>Related in this roundup: <a href="#cve-2026-27302">CVE-2026-27302</a>, <a href="#cve-2026-71398">CVE-2026-71398</a>, <a href="#cve-2026-76195">CVE-2026-76195</a>, <a href="#cve-2026-76197">CVE-2026-76197</a>.</p>
<h2 id="cve-2026-76195">CVE-2026-76195</h2>
<p>Adobe Campaign Classic (ACC) versions up to and including 7.4.4 build 9400 are vulnerable to an OS command injection flaw. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the underlying system with the privileges of the application process. This vulnerability features a changed scope and does not require user interaction for successful exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76195">https://nvd.nist.gov/vuln/detail/CVE-2026-76195</a></p>
<p>Related in this roundup: <a href="#cve-2026-27302">CVE-2026-27302</a>, <a href="#cve-2026-71398">CVE-2026-71398</a>, <a href="#cve-2026-76193">CVE-2026-76193</a>, <a href="#cve-2026-76197">CVE-2026-76197</a>.</p>
<h2 id="cve-2026-76197">CVE-2026-76197</h2>
<p>Adobe Campaign Classic is vulnerable to an OS command injection flaw due to improper neutralization of special elements in user-supplied input. An unauthenticated remote attacker can exploit this vulnerability without user interaction to execute arbitrary code on the affected system with the privileges of the application process. This vulnerability is classified as a critical RCE.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.4 build 9400)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76197">https://nvd.nist.gov/vuln/detail/CVE-2026-76197</a></p>
<p>Related in this roundup: <a href="#cve-2026-27302">CVE-2026-27302</a>, <a href="#cve-2026-71398">CVE-2026-71398</a>, <a href="#cve-2026-76193">CVE-2026-76193</a>, <a href="#cve-2026-76195">CVE-2026-76195</a>.</p>
<h2 id="cve-2026-48417">CVE-2026-48417</h2>
<p>Adobe Substance 3D Sampler is susceptible to a stack-based buffer overflow vulnerability that can be triggered when a user opens a specially crafted malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution within the security context of the logged-in user, requiring user interaction to execute.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48417">https://nvd.nist.gov/vuln/detail/CVE-2026-48417</a></p>
<p>Related in this roundup: <a href="#cve-2026-48419">CVE-2026-48419</a>, <a href="#cve-2026-48421">CVE-2026-48421</a>, <a href="#cve-2026-71382">CVE-2026-71382</a>.</p>
<h2 id="cve-2026-48418">CVE-2026-48418</h2>
<p>Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write flaw, tracked as CVE-2026-48418. A remote attacker can exploit this by tricking a user into opening a specially crafted malicious file, which may result in arbitrary code execution within the context of the currently logged-in user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48418">https://nvd.nist.gov/vuln/detail/CVE-2026-48418</a></p>
<p>Related in this roundup: <a href="#cve-2026-48420">CVE-2026-48420</a>, <a href="#cve-2026-48424">CVE-2026-48424</a>.</p>
<h2 id="cve-2026-48419">CVE-2026-48419</h2>
<p>Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write flaw, identified as CVE-2026-48419. This vulnerability allows an attacker to execute arbitrary code in the context of the current user if the user is tricked into opening a specially crafted, malicious file. Successful exploitation requires user interaction.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48419">https://nvd.nist.gov/vuln/detail/CVE-2026-48419</a></p>
<p>Related in this roundup: <a href="#cve-2026-48417">CVE-2026-48417</a>, <a href="#cve-2026-48421">CVE-2026-48421</a>, <a href="#cve-2026-71382">CVE-2026-71382</a>.</p>
<h2 id="cve-2026-48420">CVE-2026-48420</h2>
<p>Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to an out-of-bounds write vulnerability. A remote attacker could exploit this by tricking a user into opening a maliciously crafted file, leading to arbitrary code execution in the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48420">https://nvd.nist.gov/vuln/detail/CVE-2026-48420</a></p>
<p>Related in this roundup: <a href="#cve-2026-48418">CVE-2026-48418</a>, <a href="#cve-2026-48424">CVE-2026-48424</a>.</p>
<h2 id="cve-2026-48421">CVE-2026-48421</h2>
<p>Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to an out-of-bounds write flaw. An attacker can exploit this by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution within the context of the user running the application.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48421">https://nvd.nist.gov/vuln/detail/CVE-2026-48421</a></p>
<p>Related in this roundup: <a href="#cve-2026-48417">CVE-2026-48417</a>, <a href="#cve-2026-48419">CVE-2026-48419</a>, <a href="#cve-2026-71382">CVE-2026-71382</a>.</p>
<h2 id="cve-2026-48424">CVE-2026-48424</h2>
<p>Adobe Substance 3D Sampler versions 6.0.1 and earlier are vulnerable to a heap-based buffer overflow triggered by opening a specially crafted malicious file. Successful exploitation requires user interaction and can lead to arbitrary code execution within the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48424">https://nvd.nist.gov/vuln/detail/CVE-2026-48424</a></p>
<p>Related in this roundup: <a href="#cve-2026-48418">CVE-2026-48418</a>, <a href="#cve-2026-48420">CVE-2026-48420</a>.</p>
<h2 id="cve-2026-48426">CVE-2026-48426</h2>
<p>Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write vulnerability that can lead to arbitrary code execution. The vulnerability is triggered when a user opens a specially crafted malicious file, necessitating user interaction. The flaw is categorized as an out-of-bounds write (CWE-787).</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48426">https://nvd.nist.gov/vuln/detail/CVE-2026-48426</a></p>
<p>Related in this roundup: <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-48427">CVE-2026-48427</h2>
<p>Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write flaw that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption in the context of the current user session.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48427">https://nvd.nist.gov/vuln/detail/CVE-2026-48427</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-48428">CVE-2026-48428</h2>
<p>Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to a heap-based buffer overflow when processing a malicious file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, provided the user interacts with the file.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48428">https://nvd.nist.gov/vuln/detail/CVE-2026-48428</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-48430">CVE-2026-48430</h2>
<p>Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to a heap-based buffer overflow that can be triggered by enticing a user to open a specially crafted malicious file. Successful exploitation allows for arbitrary code execution within the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48430">https://nvd.nist.gov/vuln/detail/CVE-2026-48430</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-48432">CVE-2026-48432</h2>
<p>Adobe Substance 3D Designer is susceptible to a heap-based buffer overflow vulnerability that can be triggered when a user opens a specially crafted malicious file. Successful exploitation of this flaw allows an attacker to execute arbitrary code within the security context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48432">https://nvd.nist.gov/vuln/detail/CVE-2026-48432</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-48433">CVE-2026-48433</h2>
<p>Adobe Substance 3D Designer versions up to and including 16.0.4 contain a heap-based buffer overflow vulnerability. Successful exploitation requires a user to open a specially crafted malicious file, which can lead to arbitrary code execution in the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48433">https://nvd.nist.gov/vuln/detail/CVE-2026-48433</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-71564">CVE-2026-71564</a>.</p>
<h2 id="cve-2026-71360">CVE-2026-71360</h2>
<p>CAI Content Credentials, including the C2PA Tool and Content Credentials Rust SDK, is vulnerable to uncontrolled resource consumption. An unauthenticated attacker can trigger this vulnerability to exhaust system resources, resulting in a denial-of-service condition without requiring user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71360">https://nvd.nist.gov/vuln/detail/CVE-2026-71360</a></p>
<h2 id="cve-2026-71382">CVE-2026-71382</h2>
<p>Adobe Substance 3D Sampler is vulnerable to an out-of-bounds write vulnerability (CWE-787) that allows a local attacker to achieve arbitrary code execution. The vulnerability is triggered when a user is convinced to open a maliciously crafted file, making the impact dependent on user interaction.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Sampler (&lt;= 6.0.1)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71382">https://nvd.nist.gov/vuln/detail/CVE-2026-71382</a></p>
<p>Related in this roundup: <a href="#cve-2026-48417">CVE-2026-48417</a>, <a href="#cve-2026-48419">CVE-2026-48419</a>, <a href="#cve-2026-48421">CVE-2026-48421</a>.</p>
<h2 id="cve-2026-71443">CVE-2026-71443</h2>
<p>The CAI Content Credentials tools and SDK provided by Adobe contain an improper input validation vulnerability. An unauthenticated, remote attacker can exploit this flaw by sending specifically crafted input to the application, resulting in an application crash and denial-of-service condition without requiring user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71443">https://nvd.nist.gov/vuln/detail/CVE-2026-71443</a></p>
<h2 id="cve-2026-71564">CVE-2026-71564</h2>
<p>Adobe Substance 3D Designer versions 16.0.4 and earlier are vulnerable to an out-of-bounds write vulnerability. A remote attacker can trigger this vulnerability by enticing a user to open a specially crafted malicious file, leading to arbitrary code execution in the context of the current user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Designer (&lt;= 16.0.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71564">https://nvd.nist.gov/vuln/detail/CVE-2026-71564</a></p>
<p>Related in this roundup: <a href="#cve-2026-48426">CVE-2026-48426</a>, <a href="#cve-2026-48427">CVE-2026-48427</a>, <a href="#cve-2026-48428">CVE-2026-48428</a>, <a href="#cve-2026-48430">CVE-2026-48430</a>, <a href="#cve-2026-48432">CVE-2026-48432</a>, <a href="#cve-2026-48433">CVE-2026-48433</a>.</p>
<h2 id="cve-2026-75749">CVE-2026-75749</h2>
<p>Adobe Substance 3D Painter is vulnerable to an out-of-bounds write flaw (CWE-787) that can be triggered by convincing a user to open a specially crafted malicious file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the currently logged-in user.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Painter (&lt;= 12.1.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75749">https://nvd.nist.gov/vuln/detail/CVE-2026-75749</a></p>
<p>Related in this roundup: <a href="#cve-2026-75750">CVE-2026-75750</a>.</p>
<h2 id="cve-2026-75750">CVE-2026-75750</h2>
<p>Adobe Substance 3D Painter versions 12.1.2 and earlier contain a heap-based buffer overflow vulnerability. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user by convincing a victim to open a specially crafted malicious file.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Substance 3D Painter (&lt;= 12.1.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75750">https://nvd.nist.gov/vuln/detail/CVE-2026-75750</a></p>
<p>Related in this roundup: <a href="#cve-2026-75749">CVE-2026-75749</a>.</p>
<h2 id="cve-2026-75766">CVE-2026-75766</h2>
<p>Adobe Substance 3D Painter versions 12.1.2 and earlier are vulnerable to a heap-based buffer overflow triggered by opening a specially crafted malicious file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. This requires user interaction to open the file.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Painter (&lt;= 12.1.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75766">https://nvd.nist.gov/vuln/detail/CVE-2026-75766</a></p>
<p>Related in this roundup: <a href="#cve-2026-75768">CVE-2026-75768</a>, <a href="#cve-2026-75769">CVE-2026-75769</a>.</p>
<h2 id="cve-2026-75768">CVE-2026-75768</h2>
<p>Adobe Substance 3D Painter is vulnerable to an untrusted search path flaw (CWE-426), allowing a local attacker to execute arbitrary code in the context of the current user. Exploitation requires user interaction, specifically the victim opening a maliciously crafted file.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Painter (&lt;= 12.1.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75768">https://nvd.nist.gov/vuln/detail/CVE-2026-75768</a></p>
<p>Related in this roundup: <a href="#cve-2026-75766">CVE-2026-75766</a>, <a href="#cve-2026-75769">CVE-2026-75769</a>.</p>
<h2 id="cve-2026-75769">CVE-2026-75769</h2>
<p>Adobe Substance 3D Painter is vulnerable to a heap-based buffer overflow due to improper validation of user-supplied input. An attacker can exploit this by enticing a user to open a specially crafted malicious file, potentially leading to arbitrary code execution within the context of the current user session.</p>
<p>Affected products:</p>
<ul>
<li>Substance 3D Painter (&lt;= 12.1.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75769">https://nvd.nist.gov/vuln/detail/CVE-2026-75769</a></p>
<p>Related in this roundup: <a href="#cve-2026-75766">CVE-2026-75766</a>, <a href="#cve-2026-75768">CVE-2026-75768</a>.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>